Phantom in the flesh

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Phantom in the Flesh 👻
In the summer of 2025, the Threat Intelligence team of the Positive Technologies cybersecurity expert center analyzed Operation Phantom Enigma, primarily targeting residents of Brazil with the aim of stealing bank accounts. In addition to attacks on ordinary users, attacks on organizations worldwide were recorded with the goal of expanding infrastructure for further attacks.
Users were infected with malicious browser extensions for Firefox, Google Chrome, and Microsoft Edge, while organizational infrastructure fell under the control of remote management tools such as PDQ Connect or Mesh Agent.
🍂 In the fall of 2025, cyber intelligence specialists also recorded similar attacks, observing changes in toolsets and persistence techniques. For example, new RMM-class tools emerged, the logic of the attackers’ server changed, and the browser windows of Microsoft Edge and Google Chrome in victims’ systems began to cross new spaces.
👀 In our article, we described which attacks were detected, what has changed, and how widespread the actions of the Phantom Enigma group are (spoiler: fairly).
#TI #APT
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



